Burp Suite User Forum

Create new post

Limitations for recorded login sequences

Hi Support, We are in need of testing a web application that relies on google sso pop up, and as you wrote "Burp Scanner is currently unable to replay login sequences that rely on popups or <iframe> elements." there is a...

Last updated: Nov 28, 2022 11:46AM UTC | 2 Agent replies | 0 Community replies | Feature Requests

educational licence

I'm student. I can't buy PROFESSIONAL License. Can you Please give me a PROFESSIONAL. Can help me with the Pro License. Thank you.

Last updated: Nov 28, 2022 10:03AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Burp Intruder Payload Type "File"

I couldn't find an option or even an extension that takes a list of files and uses the file contents in a POST request. This would be very useful to make file upload function tests more efficient. I imagine a new payload...

Last updated: Nov 24, 2022 06:06AM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Expose IScanIssue Requests with Markers

Some scan issues contain marker information in the request/response for easier identification of issue, but there is no way to access these markers through the extender API. The IScanIssue.getHttpMessages() function...

Last updated: Nov 23, 2022 09:50AM UTC | 4 Agent replies | 3 Community replies | Feature Requests

Unable to intercept traffic of mobile application hosted over VPN

Currently facing issues with intercepting the traffic using Burp Suite from a mobile application after whitelisting the public IP address. What is achieved so far: I. Able to intercept the traffic from mobile device’s...

Last updated: Nov 17, 2022 05:23PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Enable logging on the opening screen

Hello! I think that most business users always use logging. Unfortunately sometimes we forget to turn it on under Project Settings / Misc. Could you put a checkbox in the "New project on disk" section of the opening screen...

Last updated: Nov 17, 2022 01:56PM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Reset

Can you reset all my labs expect sql injection and path traversal.

Last updated: Nov 15, 2022 09:23AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Regarding Java version

Hi, Recently we are seeing nessus vulnerability issue regarding the oracle java version as below: Plugins: 166316 Oracle Java SE Multiple Vulnerabilities (October 2022 CPU). "<plugin_output> Path :...

Last updated: Nov 11, 2022 03:08PM UTC | 7 Agent replies | 6 Community replies | Feature Requests

How does Burp Suite Enterprise choose when two configuration files conflict?

Hi, Team: We can upload more than two configuration files for a site in Burp Suite Enterprise (Settings > Configuration). but how does Burp Suite Enterprise choose when two configuration files conflict? The A...

Last updated: Nov 09, 2022 10:21AM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Content Discovery Improvements

Hi, I raised this issue a year or two back (don't recall the outcome, but it is not yet a feature)and wanted to raise it and one other again. The Content Discovery feature produces too much noise in its default...

Last updated: Nov 08, 2022 12:58PM UTC | 2 Agent replies | 0 Community replies | Feature Requests

Multiple Extensions enabled on a single click

A user by selecting multiple plugins from the list can be enabled using a single click without each extension opening a separate widow. Include a separate tab to show which extensions did not load and their respective...

Last updated: Nov 08, 2022 12:26PM UTC | 2 Agent replies | 0 Community replies | Feature Requests

Selection on Inspector

When selecting text on repeater, on inspector it shows the number of bytes. It would be helpfull to see the number of bytes also in Dec but also in Hex. In particular when performing http smuggling attacks (transfer...

Last updated: Nov 08, 2022 11:50AM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Burp Collaborator Mobile App

Dreamtime / blue sky request :-D Sometimes I'm in a situation where burp is installed on a machine that's not internet connected, but I'd still like to use the collaborator. It would be awesome if there could be a mobile...

Last updated: Nov 08, 2022 10:36AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

License Installation Limit

Hello, I have reached my license limit. I have activated the license in several VMs on my personal computer. If possible I'd require an additional activation.

Last updated: Nov 08, 2022 07:49AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Account 2FA BYPASS

Can anyone tell me how to bypass mega account recovery key it is important to me it has 10 bitcoin in it whoever securely bypass it I give 2 bitcoin to it.

Last updated: Nov 01, 2022 01:09PM UTC | 0 Agent replies | 0 Community replies | Feature Requests

Burp Collaborator question

hi, Does Burp Suite Enterprise Edition support the use of a private Burp Collaborator? and how could it be used? thanks!

Last updated: Oct 28, 2022 01:33PM UTC | 5 Agent replies | 6 Community replies | Feature Requests

Providing UDP source ports in Burp Collaborator

Is it possible to provide UDP source ports of DNS queries via the IBurpCollaboratorInteraction interface? This would allow to easily analyze the randomness of used source ports, which makes it possible to find...

Last updated: Oct 28, 2022 12:52PM UTC | 4 Agent replies | 8 Community replies | Feature Requests

Intruder payload defaults for integers

Hey, I often want to bruteforce IDs, specifically integers. I use the `Numbers` payload in Intruder. But it requires the following configuration: - Min/max integer digits - Min/max fraction digits This means every...

Last updated: Oct 27, 2022 08:52PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Add OAuth2 Support for Burp Professionnal Edition or else

Hi everyone, I've seen that "OAuth" is not on your "prior list" and i don't understand why. Everything is an API at the moment, it should be on your prior list to add this feature. Actually i need to test 2 privates...

Last updated: Oct 20, 2022 09:50AM UTC | 3 Agent replies | 3 Community replies | Feature Requests

Split screen for proxy history

It would be very handy in my opinion to have the proxy history splitted sometimes, to compare login request flows.

Last updated: Oct 19, 2022 01:33PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Page 19 of 68

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image